Skip to content

JIT: [arm32] Assertion failed 'varDsc->IsAlwaysAliveInMemory() || ((regSet.GetMaskVars() & regMask) == 0)' during 'Generate code' #105619

Description

@jakobbotsch
// Generated by Fuzzlyn v2.1 on 2024-07-28 15:37:46
// Run on Arm Linux
// Seed: 8024459297219020330
// Reduced from 3285.8 KiB to 12.2 KiB in 01:46:03
// Hits JIT assert in Release:
// Assertion failed 'varDsc->IsAlwaysAliveInMemory() || ((regSet.GetMaskVars() & regMask) == 0)' in 'Program:Main(Fuzzlyn.ExecutionServer.IRuntime)' during 'Generate code' (IL size 7170; hash 0xade6b36b; FullOpts)
// 
//     File: /__w/1/s/src/coreclr/jit/codegencommon.cpp Line: 664
// 
using System;
using System.Runtime.CompilerServices;

public interface I1
{
}

public struct S0
{
    public double F0;
    public sbyte F1;
    public ulong F2;
    public int F3;
    public ulong F4;
    public ulong F6;
    public int F7;
    public long F8;
    public S0(double f0, ulong f2, ulong f4, float f5, ulong f6, int f7, long f8) : this()
    {
    }
}

public struct S1
{
    public int F0;
    public S0 F2;
    public S0 F3;
    public S0 F4;
    public S1(int f0, double f1, S0 f2, S0 f3, S0 f4) : this()
    {
    }
}

public struct S2 : I1
{
    public S1 F2;
    public ushort F4;
    public S1 F6;
    public S1 F7;
    public S2(sbyte f0, ulong f1, S1 f2, ushort f4, byte f5, S1 f6, S1 f7) : this()
    {
    }
}

public class C0
{
    public S1 F1;
    public C0(S1 f1)
    {
    }
}

public struct S3 : I1
{
    public S3(short f0) : this()
    {
    }
}

public struct S4 : I1
{
    public S3 F0;
    public S2 F1;
    public S4(S3 f0, S2 f1, float f2, S0 f3, int f5) : this()
    {
    }
}

public struct S5
{
    public C0 F0;
    public S5(C0 f0, S1 f3) : this()
    {
    }
}

public class C1
{
    public bool F1;
}

public class Program
{
    public static IRuntime s_rt;
    public static S2 s_13;
    public static S1 s_18;
    public static bool[] s_22;
    public static C0 s_24;
    public static ushort[, ] s_31;
    public static S1 s_35;
    public static bool s_37;
    public static S5[] s_44;
    public static S4 s_54;
    public static S1 s_58;
    public static C1[, ] s_59;
    public static S4 s_60;
    public static S2 s_88;
    public static S2[] s_90;
    public static void Main()
    {
        CollectibleALC alc = new CollectibleALC();
        System.Reflection.Assembly asm = alc.LoadFromAssemblyPath(System.Reflection.Assembly.GetExecutingAssembly().Location);
        System.Reflection.MethodInfo mi = asm.GetType(typeof(Program).FullName).GetMethod(nameof(MainInner));
        System.Type runtimeTy = asm.GetType(typeof(Runtime).FullName);
        mi.Invoke(null, new object[] { System.Activator.CreateInstance(runtimeTy) });
    }

    public static void MainInner(IRuntime rt)
    {
        S0 vr8 = default(S0);
        if (s_59[0, 0].F1)
        {
            bool[] vr9 = new bool[]
            {
                true
            };
            s_88 = new S2(s_54.F1.F2.F4.F1, s_24.F1.F2.F4--, new S1(s_35.F2.F3, 0, new S0(-2, 0, 0, 0, 11218621709493063492UL, 450420498, 0), s_60.F1.F7.F2, new S0(0, 0, 0, 0, 0, 1, 0)), s_13.F4--, (byte)s_31[0, 0], new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), s_54.F1.F2);
            vr9[0] = vr9[0];
        }

        s_rt.WriteLine("c_6973", vr8.F2);
        s_rt.WriteLine("c_6975", vr8.F4);
        s_rt.WriteLine("c_6978", vr8.F7);
        I1[] vr10 = new I1[]
        {
            new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, -3.4028235E+38F, 0, 0, 0), new S0(0, 0, 0, 1, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(1, 0, new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, 0, new S0(0, 0, 16728947367172946933UL, 0, 0, 0, 0), new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))),
            new S3(0),
            new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 1, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 2102657202, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 16794536930986757818UL, 0, 0, 0, 0, 0), new S0(0, 0, 11911619636908597430UL, 0, 0, 0, 0))),
            new S3(0),
            new S2(0, 0, new S1(-2147483647, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 1, 0, new S1(0, -2, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(1, 0, 0, 0, 0, 0, 0)), new S1(1, 1, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0))),
            new S2(0, 0, new S1(0, -1, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(-1, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, -3.4028235E+38F, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))),
            new S4(new S3(0), new S2(1, 0, new S1(0, 1, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0)), 1, 0, new S1(1, 0, new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 1, 0), new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 0, 0), 0)
        };
        var vr11 = new S3(0);
        var vr12 = s_44[0].F0.F1.F3.F0;
        M75(vr11, vr12);
        if (s_22[0])
        {
            S3 vr13 = new S3(0);
            try
            {
                var vr14 = s_54.F0;
                var vr15 = s_18.F4.F0;
                S3 vr23 = vr14;
            }
            finally
            {
                var vr16 = new S3(0);
                var vr17 = s_58.F4.F0--;
                M75(vr16, vr17);
                if (s_37)
                {
                    for (int vr18 = 0; vr18 < 2; vr18++)
                    {
                        var vr19 = new S3(0);
                        vr10[0] = new S4(new S3(0), new S2(1, 5461410436353764379UL, new S1(0, 0, new S0(0, 18446744073709551614UL, 0, 0, 17533718527758593297UL, 0, 0), new S0(0, 8592301711847430801UL, 0, 0, 0, 0, 0), new S0(-1, 7862269010569978854UL, 0, 0, 0, 0, 0)), 0, 0, new S1(0, 0, new S0(0, 3156588052453432602UL, 0, 0, 0, 810788132, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(1, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 15070356010362475091UL, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 0, 0), 0);
                        vr10 = new I1[]
                        {
                            new S2(1, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, -3.4028235E+38F, 0, -1, 0), new S0(0, 7703692348755595801UL, 0, 0, 0, 0, 0)), 0, 0, new S1(1, 1.7976931348623157E+308, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0)), new S1(0, -1, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 3991586019811875011UL, 0, 0, 0, -2147483648, 0))),
                            new S4(new S3(-1), new S2(0, 9890997199408041578UL, new S1(0, 0, new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 0, -7424873608279851173L), new S0(0, 0, 9698347484967702837UL, 0, 0, 0, 0)), 0, 0, new S1(0, 0, new S0(1, 0, 0, 0, 0, 0, 8154649548600176800L), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, -9223372036854775808L)), new S1(0, 0, new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 778004003835070330UL, 0, 0, 0, 0, 0), new S0(0, 0, 8658698987098108904UL, 0, 0, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 0, 0), 956596481),
                            new S4(new S3(0), new S2(0, 453734974695362841UL, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, -8941433507005588199L)), 0, 1, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 10794758865549560580UL, 0, 7077610171127139841UL, 1, 0), new S0(1, 0, 0, 0, 0, 0, 0))), 0, new S0(1, 0, 0, 0, 17621340021635995622UL, 0, 0), 1),
                            new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, 0, new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))),
                            new S2(0, 6130557987521252430UL, new S1(0, -2, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0), new S0(1, 12555188232274105334UL, 0, 0, 0, 0, 0)), 1, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, 0, new S0(0, 1828388993980413842UL, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 5800380996067047058UL, 0, 0))),
                            new S3(1)
                        };
                        s_rt.WriteLine("c_7152", vr18);
                    }

                    S0 vr20 = new S0(0, 0, 0, 0, 0, 0, 0);
                    C0 vr21 = new C0(new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)));
                    s_rt.WriteLine("c_7159", vr20.F6);
                    s_rt.WriteLine("c_7164", vr21.F1.F0);
                    s_rt.WriteLine("c_7168", vr21.F1.F2.F2);
                    s_rt.WriteLine("c_7170", vr21.F1.F2.F4);
                    s_rt.WriteLine("c_7173", vr21.F1.F2.F7);
                    s_rt.WriteLine("c_7176", vr21.F1.F3.F1);
                    s_rt.WriteLine("c_7177", vr21.F1.F3.F2);
                    s_rt.WriteLine("c_7181", vr21.F1.F3.F6);
                    s_rt.WriteLine("c_7185", vr21.F1.F4.F1);
                    s_rt.WriteLine("c_7191", vr21.F1.F4.F7);
                    s_rt.WriteLine("c_7192", vr21.F1.F4.F8);
                }

                s_54.F1.F2.F0 = s_90[0].F6.F0++;
            }

            var vr22 = new S5(new C0(new S1(0, 0, new S0(-2, 0, 0, 0, 0, 0, 0), new S0(1, 0, 0, 0, 0, -1, 0), new S0(0, 0, 0, 0, 0, 0, 0))), new S1(0, 0, new S0(-1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)));
        }

        vr10 = new I1[]
        {
            new S4(new S3(-18643), new S2(0, 0, new S1(1, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 11398096482162480173UL, 0, 0, 0, 9223372036854775806L), new S0(0, 0, 0, 0, 0, 2134113955, 0)), 0, 0, new S1(0, 0, new S0(0, 0, 15971873843035984033UL, 0, 5979847448536525346UL, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(1, 0, 0, 0, 11276959574309188693UL, 0, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 0, 0), 0),
            new S3(1),
            new S3(0),
            new S4(new S3(0), new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 1, 0)), 1, 0, new S1(0, 0, new S0(0, 0, 0, 0, 11829847737932804605UL, 0, 0), new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, -2, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 9919258226402299883UL, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 1, 0), 0),
            new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(-1, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 1, 0), new S0(0, 0, 0, 0, 0, 0, 0))),
            new S4(new S3(0), new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(0, 1, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, -1, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(1, 0, 0, 0, 0, 0, 0))), 0, new S0(0, 0, 0, 0, 0, 1, 0), 0),
            new S4(new S3(0), new S2(0, 0, new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), 0, 0, new S1(0, 0, new S0(1, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0)), new S1(0, 0, new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0), new S0(0, 0, 0, 0, 0, 0, 0))), 0, new S0(1, 0, 0, 0, 0, 0, 0), 0),
            new S3(0),
            new S3(0),
            new S3(0)
        };
    }

    public static void M75(S3 argThis, double arg1)
    {
    }
}

public interface IRuntime
{
    void WriteLine<T>(string site, T value);
}

public class Runtime : IRuntime
{
    public void WriteLine<T>(string site, T value) => System.Console.WriteLine(value);
}

public class CollectibleALC : System.Runtime.Loader.AssemblyLoadContext
{
    public CollectibleALC() : base(true)
    {
    }
}

Attached an SPMI collection captured on 11ca923.
4BD00289.zip

Activity

  1. ghost added
    needs-area-labelAn area label is needed to ensure this gets routed to the appropriate area owners
    on Jul 29, 2024
  2. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    and removed
    untriagedNew issue has not been triaged by the area owner
    needs-area-labelAn area label is needed to ensure this gets routed to the appropriate area owners
    on Jul 29, 2024
  3. added this to the 9.0.0 milestone on Jul 29, 2024
  4. dotnet-policy-service commented on Jul 29, 2024

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  5. jakobbotsch commented on Jul 29, 2024

    @jakobbotsch
    MemberAuthor

    cc @dotnet/jit-contrib

  6. added
    Priority:2Work that is important, but not critical for the release
    on Jul 31, 2024
  7. kunalspathak commented on Sep 6, 2024

    @kunalspathak
    Contributor

    Here, we are trying to resolve V535 (float) and V533 (double) at BB09, whose predecessors are BB03 and BB08.

    BB03
    use: {V529 V537}
    def: {V02 V14 V15 V16 V17 V18 V19 V20 V23 V25 V28 V30 V32 V35 V37 V39 V42 V44 V47 V49 V52 V54 V56 V59 V61 V63 V66 V68 V71 V73 V76 V78 V80 V83 V85 V87 V90 V94 V96 V99 V101 V103 V106 V108 V110 V113 V116 V118 V120 V123 V125 V127 V130 V132 V134 V138 V140 V519 V520 V521 V522 V530 V531 V532 V533 V535 V536}
     in: {V529 V537}
    out: {V02 V530 V531 V533 V535 V537}
    Var=Reg beg of BB03: V529=r4 
    Var=Reg end of BB03: V530=f18 V535=f17 V533=f20 
    
    BB08
    use: {V531}
    def: {V290 V292 V294 V297 V299 V530 V532 V533 V535}
     in: {V531 V537}
    out: {V530 V531 V533 V535 V537}
    Var=Reg beg of BB08: none
    Var=Reg end of BB08: V530=f20 V535=f18 V533=f16 
    
    BB09
    use: {V530 V531 V533 V535 V537}
    def: {V143 V146 V148 V150 V153 V155 V157 V160 V162 V164 V168 V170 V173 V175 V178 V180 V182 V185 V187 V189 V192 V194 V196 V200 V202 V206 V208 V211 V213 V215 V218 V220 V222 V225 V228 V230 V232 V235 V237 V239 V242 V244 V246 V250 V252 V255 V257 V259 V262 V264 V266 V269 V271 V273 V277 V279 V281 V283 V285}
     in: {V530 V531 V533 V535 V537}
    out: {}
    Var=Reg beg of BB09: V530=f18 V535=f17 V533=f20 
    Var=Reg end of BB09: none
    

    At the end of BB03, we have V535=f17 and V533=f20/f21.
    At the end of BB08, we have V535=f18 and V533=f16/f17.
    At the beg of BB09, we have V535=f17 and V533=f20/f21.

    Resolution does the following:

    • For V535, it moves value from f18 to f17
    • For V533, it moves value from f16/f17 to f20/f21.

    However, the resolution of V535 happens first and when trying to move to f17, we notice that it already holds a value of a different variable, in this case V533 and we hit the assert.

    What I am trying to understand is when we decide to resolve V535, didn't we take into account that f17 is occupied because it is part of even/odd pair for double V533.

  8. added
    in-prThere is an active PR which will close this issue when it is merged
    on Sep 7, 2024
  9. modified the milestones: 9.0.0, 10.0.0 on Sep 9, 2024
  10. JulieLeeMSFT commented on Sep 9, 2024

    @JulieLeeMSFT
    Member

    Repros in .NET 8 and .NET 9. Found only in internal testing. Risky change. We will fix it in .NET 10.

  11. locked and limited conversation to collaborators on Oct 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Priority:2Work that is important, but not critical for the releasearch-arm32area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIin-prThere is an active PR which will close this issue when it is merged

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions